Nibbleblog contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a direct request for the /admin/ajax/uploader.php script, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
#(1) FD (Disclosure the Full Path) :
------------------------------------
-------------------
After upload shell-path : http://127.0.0.1/nibbleblog/content/public/upload/{File_Name_Hash}_0.php
ex image : (http://i49.tinypic.com/33lm52v.png)
Disclosure Timeline:
Disclosure Date :2013-01-14
Exploit Publish Date :2013-01-14